Ethen by Upcube
Ethen Legal & Trust Center
This is the home for the documents that govern Ethen: the Terms of Service and Privacy Policy, the rules for acceptable and responsible use, disclosures about how data moves between Ethen and the companies that help run it, product-specific policies for Studio, voice and Ethen Code, and the security material that organizations need for review. Each entry shows its version and effective date.
If you are new to Ethen, start with the Terms of Service and the Privacy Policy. If you are evaluating Ethen for an organization, the Enterprise Security document describes current controls, their limits and the materials available for a security or procurement review.
What these documents cover today
- Available now: Ethen Chat at chat.upcube.ai, including voice and web research, and Ethen Studio in early access. Both run in the cloud and send your prompts to the model provider that answers them, as named in the Subprocessors list.
- Not yet available: Ethen Code and its desktop app, connected apps, bring-your-own-key access, file uploads, Organization accounts and paid plans. The policies for these explain how they are designed to work and say plainly that they are not live.
- No certifications: Ethen does not hold SOC 2, ISO 27001 or other security or compliance certifications today.
Security and organizational review
Current controls include managed sign-in, database isolation between accounts, server-side secrets, encrypted connections and emergency shut-off switches. These controls have limits: there is no independent penetration test report, dedicated security-monitoring system or tamper-evident audit log today. The Enterprise Security document explains the details and recovery limits. The Privacy Policy and Subprocessors list describe how data reaches providers.
Organizations should evaluate the available products, data flows, approval controls and records against their own requirements. Connected apps and organizational administration are not yet available; planned approvals and records are not a compliance archive. Product plans do not establish that a feature is live, and these documents do not promise certification or audit readiness. Availability and limitations are stated here so reviewers can distinguish current capabilities from intended work.